Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2005-0332
Description:Directory traversal vulnerability in DeskNow Mail and Collaboration Server 2.5.12 allows remote attackers to (1) upload and possibly execute files outside the directory via the AttachmentsKey parameter to attachment.do, as demonstrated using JSP pages, or (2) delete arbitrary files via the select_file parameter to file.do.
Test IDs: 1.3.6.1.4.1.25623.1.0.16308  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2005-0332
BugTraq ID: 12421
http://www.securityfocus.com/bid/12421
Bugtraq: 20050202 [SIG^2 G-TEC] DeskNow Mail and Collaboration Server Directory Traversal Vulnerabilities (Google Search)
http://marc.info/?l=bugtraq&m=110737616324614&w=2
http://www.security.org.sg/vuln/desknow2512.html
http://securitytracker.com/id?1013060
http://secunia.com/advisories/14116
XForce ISS Database: desknow-attachmentkey-file-upload(19206)
https://exchange.xforce.ibmcloud.com/vulnerabilities/19206
XForce ISS Database: desknow-filedo-file-deletion(19212)
https://exchange.xforce.ibmcloud.com/vulnerabilities/19212
XForce ISS Database: desknow-jsp-gain-access(19211)
https://exchange.xforce.ibmcloud.com/vulnerabilities/19211




© 1998-2025 E-Soft Inc. All rights reserved.